Skip to content
← Back to the toolkit

GDPR

Regulation (EU) 2016/679 on the processing of personal data and the protection of the fundamental rights and freedoms of natural persons.

The General Data Protection Regulation (GDPR) is the European Union’s framework for processing personal data. It assigns duties to controllers and processors and gives data subjects enforceable rights. Those rights have conditions, procedures and exceptions; they are not unconditional instructions to disclose, change or delete every record.

Selected rights

  • Access (Art. 15): confirmation, access to personal data and the information specified by the regulation, subject to protections such as the rights and freedoms of others.
  • Rectification (Art. 16): correction of inaccurate personal data and completion of incomplete data, taking account of the processing purpose.
  • Erasure (Art. 17): erasure where a statutory ground applies; legal exceptions may require or permit retention.
  • Portability (Art. 20): for eligible automated processing based on consent or contract, receipt of data provided by the person in a structured, commonly used and machine-readable format, and direct transmission where technically feasible.
  • Objection (Art. 21): a qualified right for specified processing and an unconditional right to stop processing for direct marketing.

Controllers normally respond without undue delay and within one month. Lawful extensions, identity checks, restrictions and exceptions may apply.

Selected duties

Controllers must identify a lawful basis and ensure processing follows principles such as purpose limitation, data minimisation, accuracy, storage limitation, security and accountability. When a controller engages a processor, a binding contract or other legal act must contain the terms required by Art. 28.

A controller notifies the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to risk people’s rights and freedoms. Communication to affected people follows the separate, higher threshold in Art. 34.

Relationship to sovereignty

The GDPR forms part of data complianceData complianceThe enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.Read more →in the Organisational layer. It sets boundaries on the legitimate exercise of control but does not by itself establish that an organisation can operate independently or leave a supplier. A service can comply with the GDPR and still create lock-in, while technically independent infrastructure can still be used unlawfully or irresponsibly.

This page is a concise orientation, not legal advice or a compliance verdict.

Sources

  • European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. Official Journal of the European Union, L 119, 1–88. EUR-Lex
  • European Data Protection Board. (n.d.). Guidelines, recommendations and best practices. EDPB

Put this to work

Related concept

Data compliance

The enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.

Related concept

Data ethics

A separate governance perspective on the Organisational layer: asking whether the exercise of scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected.

Copyright 2026HOIST IT. All Rights Reserved